PT-2020-19879 · One Identity · One Identity Password Manager
Clément Cruchet
·
Published
2020-11-13
·
Updated
2021-07-21
·
CVE-2020-7962
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
One Identity Password Manager version 5.8
Description
An issue was discovered in One Identity Password Manager where an attacker could enumerate valid answers for a user. This is possible because the HTTP response content returns 'WRONG ID' only when the answer is incorrect, allowing an attacker to detect a valid answer and reuse it later for a password reset on a chosen password.
Recommendations
For One Identity Password Manager version 5.8, consider restricting access to the password reset functionality until a patch is available. As a temporary workaround, modify the HTTP response content to not disclose whether the answer is correct or not, preventing attackers from enumerating valid answers. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
One Identity Password Manager